C795- Cybersecurity Management II -
Tactical
Security Tests - answer Security tests verify that a control is functioning properly. These
tests include automated scans, tool-assisted penetration tests, and manual attempts to
undermine security. Security testing should take place on a regular schedule, with
attention paid to each of the key security controls protecting an organization.
Security Assessments - answer Comprehensive reviews of the security of a system,
application, or other tested environment. During a security assessment, a trained
information security professional performs a risk assessment that identifies
vulnerabilities in the tested environment that may allow a compromise and makes
recommendations for remediation, as needed.
NIST SP 800-53A - answer Guide for Assessing the Security Controls an privacy
controls in Federal Information Systems
Security Audits - answerUse many of the same techniques followed during security
assessments but must be performed by independent auditors. Audits are performed
with the purpose of demonstrating the effectiveness of controls to a third party. Auditors
provide an impartial, unbiased view of the organization's security controls.
Internal Audits - answerPerformed by an organization's internal audit staff and are
typically intended for internal audiences.
External Audits - answerExternal audits are performed by an outside auditing firm.
These audits have a high degree of external validity because the auditors performing
the assessment theoretically have no conflict of interest with the organization itself.
Audits performed by these firms are generally considered acceptable by most investors
and governing body members.
SAE 18 - answerThe Statement on Standards for Attestation Engagements document
18. SAE 18, titled Reporting on Controls , provides a common standard to be used by
auditors performing assessments of service organizations with the intent of allowing the
organization to conduct an external assessment instead of multiple third- party
assessments and then sharing the resulting report with customers and potential
customers. Outside of the United States, similar engagements are conducted under the
International Standard for Attestation Engagements (ISAE) 3402, Assurance Reports on
Controls at a Service Organization .
,Service Organization Controls (SOC) Audits - answerSSAE 18 and ISAE 3402
engagements are commonly referred to as service organization controls (SOC) audits,
and they come in three forms:
SOC 1 Engagements
SOC 2 Engagements
SOC 3 Engagements
SOC 1 Engagements - answerAssess the organization's controls that might impact the
accuracy of financial reporting.
SOC 2 Engagements - answerAssess the organization's that affect the security
(Confidentiality, Integrity, and Availability) and privacy of information stored in a system.
Confidential, and are normally only shared outside the organization under an NDA.
SOC 3 Engagements - answerAssess the organization's that affect the security
(Confidentiality, Integrity, and Availability) and privacy of information stored in a system.
SOC 3 audit results are intended for public disclosure.
Type I Report - answerProvides the auditor's opinion on the description provided by
management and the suitability of the design of the controls. Usually focuses on a
specific point in time.
Type II Report - answerProvides the auditor's opinion on the operating effectiveness of
the controls. Covers an extended period of time.
Control Objectives for Information and Related Technology (COBIT) - answerCOBIT
describes the common requirements that organizations should have in place
surrounding their information systems. The COBIT framework is maintained by ISACA.
International Organization for Standardization (ISO) - answerPublishes a set of
standards for information security.
ISO 27001 - answerThe ISO (International Organization for Standardization) 27001
standard is a code of practice for implementing an information security management
system, against which organizations can be certified.
ISO 27002 - answerThe ISO (International Organization for Standardization) 27002
standard is a code of practice for information security with hundreds of potential controls
and control mechanisms. The standard is intended to provide a guide for the
development of "organizational security standards and effective security management
practices and to help build confidence in inter-organizational activities".
Vulnerabilities - answerWeaknesses in systems and security controls that might be
exploited by a threat.
, Security Content Automation Protocol (SCAP) - answerA NIST framework that outlines
various accepted practices for automating vulnerability scanning.
Common Vulnerabilities and Exposures (CVE) - answerProvides a naming system for
describing security vulnerabilities.
Common Vulnerability Scoring System (CVSS) - answerProvides a standardized
scoring system for describing the severity of security vulnerabilities.
Common Configuration Enumeration (CCE) - answerProvides a naming system for
system configuration issues.
Common Platform Enumeration (CPE) - answerProvides a naming system for operating
systems, applications, and devices.
Extensible Configuration Checklist Description Format (XCCDF) - answerProvides a
language for specifying security checklists.
Open Vulnerability and Assessment Language (OVAL) - answerProvides a language for
describing security testing procedures.
Network Discovery Scanning - answerUses a variety of techniques to scan a range of IP
addresses, searching for systems with open ports.
TCP SYN Scanning - answerSends a single packet to each scanned port with the SYN
flag set.
-aka "half-open" scanning
-looking to see if receives the SYN and ACK flags
TCP Connect Scanning - answerOpens a full connection to the remote system on the
specific port.
-used when the user does not have necessary perm's to run a half-open scan.
TCP ACK Scanning - answerSends a packet with the ACK flag set, indicating that it is
part of an open connection. May be done to attempt to determine the rules enforced by
the firewall, and the firewall methodology.
UDP Scanning - answerPerforms a scan of the remote system using the UDP protocol,
checking for active UDP services. Does not use the 3-way handshake because UDP is
a connectionless protocol.
Xmas Scanning - answerSends a packet with the FIN, PSH, and URG flags set
-a packet with so many flags lit is said to be "lit up like an xmas tree"
Nmap - answerA command-line tool used to scan networks. It is a type of network
scanner.
Tactical
Security Tests - answer Security tests verify that a control is functioning properly. These
tests include automated scans, tool-assisted penetration tests, and manual attempts to
undermine security. Security testing should take place on a regular schedule, with
attention paid to each of the key security controls protecting an organization.
Security Assessments - answer Comprehensive reviews of the security of a system,
application, or other tested environment. During a security assessment, a trained
information security professional performs a risk assessment that identifies
vulnerabilities in the tested environment that may allow a compromise and makes
recommendations for remediation, as needed.
NIST SP 800-53A - answer Guide for Assessing the Security Controls an privacy
controls in Federal Information Systems
Security Audits - answerUse many of the same techniques followed during security
assessments but must be performed by independent auditors. Audits are performed
with the purpose of demonstrating the effectiveness of controls to a third party. Auditors
provide an impartial, unbiased view of the organization's security controls.
Internal Audits - answerPerformed by an organization's internal audit staff and are
typically intended for internal audiences.
External Audits - answerExternal audits are performed by an outside auditing firm.
These audits have a high degree of external validity because the auditors performing
the assessment theoretically have no conflict of interest with the organization itself.
Audits performed by these firms are generally considered acceptable by most investors
and governing body members.
SAE 18 - answerThe Statement on Standards for Attestation Engagements document
18. SAE 18, titled Reporting on Controls , provides a common standard to be used by
auditors performing assessments of service organizations with the intent of allowing the
organization to conduct an external assessment instead of multiple third- party
assessments and then sharing the resulting report with customers and potential
customers. Outside of the United States, similar engagements are conducted under the
International Standard for Attestation Engagements (ISAE) 3402, Assurance Reports on
Controls at a Service Organization .
,Service Organization Controls (SOC) Audits - answerSSAE 18 and ISAE 3402
engagements are commonly referred to as service organization controls (SOC) audits,
and they come in three forms:
SOC 1 Engagements
SOC 2 Engagements
SOC 3 Engagements
SOC 1 Engagements - answerAssess the organization's controls that might impact the
accuracy of financial reporting.
SOC 2 Engagements - answerAssess the organization's that affect the security
(Confidentiality, Integrity, and Availability) and privacy of information stored in a system.
Confidential, and are normally only shared outside the organization under an NDA.
SOC 3 Engagements - answerAssess the organization's that affect the security
(Confidentiality, Integrity, and Availability) and privacy of information stored in a system.
SOC 3 audit results are intended for public disclosure.
Type I Report - answerProvides the auditor's opinion on the description provided by
management and the suitability of the design of the controls. Usually focuses on a
specific point in time.
Type II Report - answerProvides the auditor's opinion on the operating effectiveness of
the controls. Covers an extended period of time.
Control Objectives for Information and Related Technology (COBIT) - answerCOBIT
describes the common requirements that organizations should have in place
surrounding their information systems. The COBIT framework is maintained by ISACA.
International Organization for Standardization (ISO) - answerPublishes a set of
standards for information security.
ISO 27001 - answerThe ISO (International Organization for Standardization) 27001
standard is a code of practice for implementing an information security management
system, against which organizations can be certified.
ISO 27002 - answerThe ISO (International Organization for Standardization) 27002
standard is a code of practice for information security with hundreds of potential controls
and control mechanisms. The standard is intended to provide a guide for the
development of "organizational security standards and effective security management
practices and to help build confidence in inter-organizational activities".
Vulnerabilities - answerWeaknesses in systems and security controls that might be
exploited by a threat.
, Security Content Automation Protocol (SCAP) - answerA NIST framework that outlines
various accepted practices for automating vulnerability scanning.
Common Vulnerabilities and Exposures (CVE) - answerProvides a naming system for
describing security vulnerabilities.
Common Vulnerability Scoring System (CVSS) - answerProvides a standardized
scoring system for describing the severity of security vulnerabilities.
Common Configuration Enumeration (CCE) - answerProvides a naming system for
system configuration issues.
Common Platform Enumeration (CPE) - answerProvides a naming system for operating
systems, applications, and devices.
Extensible Configuration Checklist Description Format (XCCDF) - answerProvides a
language for specifying security checklists.
Open Vulnerability and Assessment Language (OVAL) - answerProvides a language for
describing security testing procedures.
Network Discovery Scanning - answerUses a variety of techniques to scan a range of IP
addresses, searching for systems with open ports.
TCP SYN Scanning - answerSends a single packet to each scanned port with the SYN
flag set.
-aka "half-open" scanning
-looking to see if receives the SYN and ACK flags
TCP Connect Scanning - answerOpens a full connection to the remote system on the
specific port.
-used when the user does not have necessary perm's to run a half-open scan.
TCP ACK Scanning - answerSends a packet with the ACK flag set, indicating that it is
part of an open connection. May be done to attempt to determine the rules enforced by
the firewall, and the firewall methodology.
UDP Scanning - answerPerforms a scan of the remote system using the UDP protocol,
checking for active UDP services. Does not use the 3-way handshake because UDP is
a connectionless protocol.
Xmas Scanning - answerSends a packet with the FIN, PSH, and URG flags set
-a packet with so many flags lit is said to be "lit up like an xmas tree"
Nmap - answerA command-line tool used to scan networks. It is a type of network
scanner.